
1-4
detection entry is aged out, the device generates an alarm and filters out ARP packets sourced from
that MAC address (in filter mode), or only generates an alarm (in monitor mode).
A gateway or critical server may send a large number of ARP packets. To prevent these ARP packets
from being discarded, you can specify the MAC address of the gateway or server as a protected MAC
address. A protected MAC address is excluded from ARP attack detection even if it is an attacker.
Only the ARP packets delivered to the CPU are detected.
Configuration Procedure
Follow these steps to configure source MAC address based ARP attack detection:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enable source MAC address
based ARP attack detection
and specify the detection mode
arp anti-attack source-mac
{
filter
|
monitor
}
Required
Disabled by default.
Configure the threshold
arp anti-attack source-mac
threshold threshold-value
Optional
50 by default.
Configure the aging timer for
source MAC address based
ARP attack detection entries
arp anti-attack source-mac
aging-time time
Optional
Five minutes by default.
Configure protected MAC
addresses
arp anti-attack source-mac
exclude-mac
mac-address
&<1-10>
Optional
Not configured by default.
After an ARP attack detection entry expires, the MAC address of the entry becomes ordinary.
Displaying and Maintaining Source MAC Address Based ARP Attack Detection
To do…
Use the command…
Remarks
Display attacking entries
detected
display arp anti-attack source-mac
{
slot
slot-number | interface
interface-type
interface-number
}
Available in any
view
Configuring ARP Packet Source MAC Address Consistency Check
Introduction
This feature enables a gateway device to filter out ARP packets with the source MAC address in the
Ethernet header different from the sender MAC address in the ARP message, so that the gateway
device can learn correct ARP entries.
Содержание S5120-EI Series
Страница 139: ...ii...
Страница 268: ...3 3 SwitchB system view SwitchB interface vlan interface 1 SwitchB Vlan interface1 ip address dhcp alloc...
Страница 328: ...i Table of Contents 1 Dual Stack Configuration 1 1 Dual Stack Overview 1 1 Configuring Dual Stack 1 1...
Страница 578: ...1 21 C...
Страница 739: ...1 12 Enable ARP detection based on 802 1X security entries SwitchB arp detection mode dot1x...
Страница 926: ...2 8...
Страница 942: ...ii Single Device Upgrade 3 4 IRF System Upgrade 3 5...
Страница 985: ...1 1...
Страница 1018: ...1 6...